PT-2026-77273 · Context7 · Context7
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Context7 versions prior to 2.1.2
Description
A prompt injection issue exists where unsanitized content can be injected through the Custom AI Instructions feature served via the MCP server. This allows attackers to execute malicious instructions in connected AI coding agents. Potential impacts include the exfiltration of credentials from environment files to an external service and the destructive deletion of files on the victim's machine during routine library documentation requests.
Recommendations
Update Context7 to version 2.1.2 or later.
Restrict the use of the Custom AI Instructions feature until the update is applied.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Context7